Cannot get multiple VLANs to work on one port for one PC on an Cisco SG300 switch.

I have a guest network that was setup kinda odd (not by me).
The management part of this network is on VLAN99 and runs in the 192.168.1.x address space.
This address space includes all the switches, access points, access point controllers and one management PC.

The guest part of this network is on VLAN100 and runs in the 192.168.111.x address space.
The Cisco WLC controller gives out DHCP addresses in the 192.168.111.x space and uses the gateway address of 192.168.111.1, which is a Sonicwall firewall (which is managed by Spectrum business solutions... don't ask).

If you login to the management PC you can manage the WLC and all the switches just fine.
However, because you are on VLAN99 and in the 192.168.1.x address space you cannot get to the internet.

If you login tot he WIFI you cannot manage any hardware but you can get to the internet.

This IS how it is supposed to work.

However, I would like to monitor the firewall, via SNMP, from my management PC on the 192.168.1.x network.

I have assigned a 192.168.111.x address to the PC as it's main address.
I have assigned VLAN100 as an additional VLAN on the port that it's plugged into.
But, it does not work.

The switch that I'm plugged into is a Cisco SG300-10SPF

The port I'm using is configured as:
interface gigabitethernet8
 description "Management PC Link"
 switchport trunk allowed vlan add 100

Open in new window


On the 3650 line of switches that would allow VLAN99 (the default VLAN on the switch) and VLAN100 to use port 8.
On this switch... it just doesn't work.

I'm open to ideas.
LVL 3
Jeff MorlenNetwork EngineerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

SouljaSr.Net.EngCommented:
Is your pc tagging traffic out of it's nic with a vlan id? If not, that port configuration is incorrect. It just needs to be a normal access port on vlan 100.

switchport access vlan 100

Open in new window

Jeff MorlenNetwork EngineerAuthor Commented:
Soulja-
If I use that command I bind myself only to VLAN100.
I need access to VLAN99 and VLAN100, which should be a trunk function.

I guess the question could be...
If I cannot tag my traffic on the PC to use either VLAN99 or VLAN100 would/could this ever work?
SouljaSr.Net.EngCommented:
If you are trying to use the same pc nic, you will need to be able to tag the vlans from your pc's nic. Otherwise, you can only do one vlan.  If you have multiple nics then each could connect into their respective ports on the switch for that specific vlan.
SolarWinds® IP Control Bundle (IPCB)

Combines SolarWinds IP Address Manager and User Device Tracker to help detect IP conflicts, quickly identify affected systems, and help your team take near instantaneous action. Help improve visibility and enhance reliability with SolarWinds IP Control Bundle.

Jeff MorlenNetwork EngineerAuthor Commented:
I'm working on getting a VLAN tagging driver to try to fix this now.
I'll update this question as soon as I get this either fixed or abandon.  :)
SouljaSr.Net.EngCommented:
Even when you do, you will need to be able to differentiate which address will use which vlan tag or one use a tag and the other not tag. Then configure other untagged vlan as native. This would be ideal for a hypervisor endhost.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
atlas_shudderedSr. Network EngineerCommented:
Couple thoughts on this.

To accomplish what you are currently proposing, you will need to set the NIC on your PC up as port-channel/etherchannel with vlan tagging enabled as noted by Soulja above.  Additionally, you will need to have a soft switch on the PC.  Are you running VM on this box?  If not, then even your tagging is inconsequential as there is really nothing to diff between the two vlans on the PC - unless there is something you haven't stated yet?

Both of these VLANS are on the same switch correct?  They separated by what?  An ACL?
nociSoftware EngineerCommented:
Isn't it simpler to create a router with a severly restricted firewall between VLAN 99 & VLAN 100?
Jeff MorlenNetwork EngineerAuthor Commented:
SOLUTION:
Windows does not load the A.N.D. driver by default.
I had to download the Advanced Networking Driver from Intel.

Once installed, I configured VLAN99 and VLAN100.
Neither worked.

I then "untagged" VLAN99 and everyting is now working.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VLAN

From novice to tech pro — start learning today.